Market / Code security scan
External service · publisher supplied metadata

Code security scan

Static security scan of a code snippet. Finds hardcoded secrets (AWS keys, private keys, API keys, DB connection strings with passwords), eval/exec, command injection, HTTP calls with no timeout, weak hashes (md5/sha1), bare except and unverified JWT. Returns one entry per finding with rule, severity, exact line number, the offending line and a suggested fix. Rule-based and deterministic: no LLM, so the same snippet always returns the same findings. Send Python or JavaScript as plain text. Not a

APIx402Indexed

Listing completeness · 80/100

Presence of published information only. Not a security, reliability or performance score. Same rules for Datoka and external listings.

Name and traceable source
10/10 · Present
Meaningful description
10/10 · Present
Connection or installation reference
20/20 · Present
Dedicated documentation or source repository
0/15 · Missing or insufficient
Explicit free access or numeric tariff
20/20 · Present
Declared integration protocol
10/10 · Present
Source updated within 90 days
10/10 · Present
Declared capability names
0/5 · Missing or insufficient

Evaluated 2026-10-08 · Method listing-completeness-1. Scoring rules

Connect & use

Connect through the publisher’s supported interface. Any credentials or payments are handled by the provider.

x402 resource

https://fachada.chelsea-hermes.workers.dev/scan/v1/code/scan

Read the current payment requirements with a compatible client before authorizing a call.

Documentation ↗Publisher website ↗

Categories and declared capabilities

Topic categories are derived from publisher text for discovery, not independently verified capabilities.

The registry does not provide a verified tools list. See the observations, when available, for any tools/list check; a published tools list does not establish that execution succeeds.

Evidence, with its limits.

This listing is indexed. Any domain claim or endpoint observation appears separately with its date and limited scope. No payment execution, factual accuracy or safety certification is inferred.

The listing completeness score measures published information only. No safety or performance score has been assigned. A signature, source listing or successful HTTP response does not certify factual accuracy or safety.
How verification states work →